Microsoft Threat Intelligence identifies a campaign using blockchain-stored malware to bypass takedowns and steal corporate credentials.
Hackers are leveraging BNB Smart Chain contracts to distribute malware through compromised websites and deceptive CAPTCHA prompts. The technique, dubbed EtherHiding, embeds malicious instructions in blockchain smart contracts, making removal difficult as only the controlling wallet can alter the code.
The campaign, linked to the ClearFake malware family, injects JavaScript into hacked sites to fetch commands from a BNB Chain gateway. Victims encounter fake CAPTCHAs instructing them to paste and execute attacker-supplied commands via Windows tools like Run, Terminal, or PowerShell. Microsoft researchers classify this as a high-volume initial access method.
Successful attacks enable credential theft and persistent network access. The use of decentralized storage complicates traditional takedown efforts, highlighting evolving cybersecurity threats targeting corporate systems.